LIVE NEWS
  • US Army’s 7th Infantry Division, 1st MDTF to merge as Multi-Domain Command-Pacific
  • Science news this week: PCOS has a new name, Neanderthals were the world’s oldest dentists, and the first nuclear bomb explosion spawned an ‘alien’ crystal
  • London police prepare for a busy day with two big rallies planned and a soccer final
  • Dogecoin Presses Resistance After Brutal Week: $3Bn Signal Real?
  • Funnel Builder WordPress plugin bug exploited to steal credit cards
  • This hedge fund just dumped the ‘big three’ airline stocks, as the industry faces soaring fuel costs
  • After Mythos, Australia should prepare to battle for access to frontier AI
  • Top 5 Japanese AI and Chip Stocks to Watch, According to Mizuho
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Funnel Builder WordPress plugin bug exploited to steal credit cards
Cybersecurity

Funnel Builder WordPress plugin bug exploited to steal credit cards

primereportsBy primereportsMay 16, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Funnel Builder WordPress plugin bug exploited to steal credit cards
Share
Facebook Twitter LinkedIn Pinterest Email


Funnel Builder WordPress plugin bug exploited to steal credit cards

A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages.

The flaw has not received an official identifier and can be leveraged without authentication. It affects all versions of the plugin before 3.15.0.3.

Funnel Builder is a WordPress plugin for WooCommerce Checkout developed by FunnelKit, primarily used to customize checkout pages, with features like one-click upsells, landing pages, and to optimize conversion rates.

Based on statistics from WordPress.org, the Funnel Builder plugin is active on more than 40,000 websites.

E-commerce security company Sansec detected the malicious activity and noticed that the payload (analytics-reports[.]com/wss/jquery-lib.js) is disguised as a fake Google Tag Manager/Google Analytics script that opens a WebSocket connection to an external location (wss://protect-wss[.]com/ws).

An attacker can exploit it to modify the plugin’s global settings via an unprotected, publicly exposed checkout endpoint. This allows them to inject arbitrary JavaScript into the plugin’s “External Scripts” setting, causing malicious code to execute on every checkout page.

According to Sansec, the attacker-controlled server delivers a customized payment card skimmer that steals the following information:

  • Credit card numbers
  • CVVs
  • Billing addresses
  • Other customer information

Payment card skimmers enable threat actors to make fraudulent online purchases, while stolen records often end up sold individually or in bulk on dark web portals known as carding markets.

FunnelKit addressed the vulnerability in version 3.15.0.3 of Funnel Builder, released yesterday.

A security advisory from the vendor, seen by Sansec, confirms the malicious activity, saying “we identified an issue that allowed bad actors to inject scripts.”

The vendor recommends that website owners and administrators prioritize updating to the latest version from the WordPress dashboard and also review Settings > Checkout > External Scripts for potential rogue scripts the attacker may have added.


article image

Automated pentesting tools deliver real value, but they were built to answer one question: can an attacker move through the network? They were not built to test whether your controls block threats, your detection rules fire, or your cloud configs hold.

This guide covers the 6 surfaces you actually need to validate.

Download Now

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThis hedge fund just dumped the ‘big three’ airline stocks, as the industry faces soaring fuel costs
Next Article Dogecoin Presses Resistance After Brutal Week: $3Bn Signal Real?
primereports
  • Website

Related Posts

Cybersecurity

The Boring Stuff is Dangerous Now

May 15, 2026
Cybersecurity

Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence

May 15, 2026
Cybersecurity

American Lending Center Data Breach Affects 123,000 Individuals

May 15, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20258 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20265 Views

German Chancellor Merz faces difficult mission to Israel – DW – 12/06/2025

December 6, 20254 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • US Army’s 7th Infantry Division, 1st MDTF to merge as Multi-Domain Command-Pacific
  • Science news this week: PCOS has a new name, Neanderthals were the world’s oldest dentists, and the first nuclear bomb explosion spawned an ‘alien’ crystal
  • London police prepare for a busy day with two big rallies planned and a soccer final
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.